For the complete documentation index, see llms.txt. This page is also available as Markdown.

Authoring

Guidelines for authoring frameworks, risk matrices, journey presets, and Excel-driven content

This section gathers the authoring guidelines — the conventions, structure, and pitfalls to keep in mind when you create the content that drives CISO Assistant: frameworks, risk matrices, journey presets, and Excel-driven library content.

Authoring is a separate discipline from running the platform. Once content has been authored, it's loaded through the Libraries section and behaves the same as any built-in content — versioned, upgradable, exportable. The pages here focus on writing the content, not on loading it.

For frameworks, matrices, and presets, the recommended path is the in-app visual editor. These are now unified in a single Library builder under the /experimental/ namespace: you author a whole library as a draft document — never touching live objects — then publish it through the standard loader, or export/import it as YAML. Draft/publish lifecycle, live preview, real-time validation, and multi-language support all apply. Excel-driven authoring remains the right channel for library publishing across instances.

What's in this section

  • Library builder — the unified entry point for authoring library content in the app: author a full library (or a single framework/matrix in simple mode), build requirement trees, matrices, threats, reference controls, and journey presets, adopt or clone existing content, import/export YAML, and publish through the standard loader.

  • Excel-driven authoring — the recommended workflow for authoring frameworks, matrices, and other library content from Excel before conversion to YAML.

When to read this section

  • You're building your own framework (industry-specific, internal policy, regulatory adaptation) and want to do it right the first time.

  • You're forking an existing framework as a baseline — copying a built-in or community library, then tuning it to your context (renaming the URN, pruning, adding in-house requirements) rather than starting from a blank page.

  • You're modelling a custom risk matrix that needs to match your enterprise's existing risk taxonomy.

  • You're standardising a journey preset for a recurring assessment pattern (yearly ISO audit, supplier onboarding, new project intake).

  • You want to understand the editorial rules behind the platform's built-in content before contributing or forking it.

Last updated

Was this helpful?